Skip to content

How healthy is your infrastructure? One score, fully explained.

Denetta is a read-only IT infrastructure security audit platform developed by Bilgi Teknoloji: it audits FortiGate firewalls, switches and routers and a company’s domains without writing to any device, turns configuration into concrete findings with expert rule sets, and combines them into a single 0-100 Infrastructure Health Score justified rule by rule. It is multi-tenant for MSPs and hosted in Türkiye.

  • Read-only, never writes
  • Device access requires signed consent
  • Hosted in Türkiye

Infrastructure Health Score

Sample view
67/100

14 findings · 1 critical · 4 high

  • Firewall58
  • Network devices81
  • Domain and email72
  • Cloudout of scope

Categories you don’t use never lower your score.

165

expert audit rules

189

items in the measured FortiGate checklist

19

network device vendor profiles

443

outbound only — no inbound ports required

0

write commands sent to devices

Findings, not metrics: what does Denetta find?

RMM watches endpoints, NMS watches the network, CVE scanners watch vulnerabilities. Management has one question: “How healthy is our infrastructure?” Denetta answers it with findings that name the exact record, not with charts:

  • Critical

    Unrestricted management access open from the WAN

    Firewall · management plane

  • Critical

    FortiOS version affected by an actively exploited vulnerability

    Vulnerability · CISA KEV

  • High

    Default SNMP community name ('public')

    Network devices

  • High

    No DMARC record

    Domain and email

How does Denetta work?

We never ask you to open a port into your network; the collector only talks outbound, over 443.

  1. 01

    Signed consent and scope

    Scans that connect to a device start only with the customer’s signed and stamped written consent; the sites, IP blocks and domains to be audited are limited by that signature.

  2. 02

    Read-only collection

    Data comes from a file upload, the device’s read-only API or a collector in the customer segment; no path contains a write command.

  3. 03

    Expert audit

    Every category runs through its own expert rule set. Data that cannot be read is never counted as “passed”; it is reported as a “visibility gap”.

  4. 04

    Score and remediation

    The score comes with a rule-by-rule breakdown; remediation commands are shown in the device vendor’s syntax and are never executed.

What does it audit today, and what is next?

Available today
  • Firewall Audit

    Expert-rule audit of FortiGate configuration: policy, management plane, VPN, HA, security profiles (121 rules).

  • FortiOS Vulnerability Matching

    FortiOS version matched against CVE.org, CISA KEV and FIRST EPSS data; no exploit attempts.

  • Firewall Monitoring

    Scheduled read-only scans, alerts on unannounced config changes and score trend; full backup archive in early access.

  • Network Device Audit

    Read-only audit of switches and routers over SNMP/SSH; 19 vendor profiles, vendor-specific remediation text.

  • Domain and Email Security

    Outside-in audit of SPF, DKIM, DMARC, MTA-STS, MX STARTTLS, web certificates, DNSSEC and domain registration.

  • Rule Cleanup

    Unused rules and objects, shadowing, rule recertification workflow.

  • Microsoft 365 Tenant Audit

    MFA enforcement, privileged roles, legacy authentication and external sharing, audited with read-only consent.

  • Compliance Packs

    Gap report and evidence pack against KVKK, Law 5651, ISO 27001 and PCI DSS.

  • Access and Segmentation Analysis

    Zone/segment access matrix and internet-exposed surface map.

  • Change Planning

    Change request and approval workflow, verified on the next scan; nothing is sent to the device.

  • Law 5651 Access Log Archive

    Tamper-evident archive of FortiGate access logs; does not replace the legal retention obligation.

  • Security Event Monitoring

    FortiGate events; the first slice is VPN sessions and connected-time reporting.

  • Windows Server and Active Directory

    FSMO, replication, DNS/DHCP consistency, patch compliance.

  • Servers, hardware and storage

    Linux, iLO/iDRAC Redfish, RAID and SMART health.

  • Cloud

    Azure, AWS and GCP audited through a read-only role.

  • IoT and cameras

    Passive discovery, default-credential database matching and CVE matching.

Why do we say “never writes to a device”?

Because it isn’t a feature; it is the product’s identity: Denetta has no protection or intervention plane, and never will. Only show / get / display commands, SNMP GET/WALK and read-only API calls are used; vulnerabilities are detected by version ⇄ CVE matching, never by exploit attempts.

We also check whether the account you give us is truly read-only and restricted by source IP, and write the result into your report as a finding. The auditor’s access is audited too.

Does it replace your RMM?

No, it sits on top of it. Your Zabbix, NinjaOne or RMM stays in charge of real-time monitoring; Denetta adds a layer of periodic deep audits, scoring and expert analysis on top.

Quick questions

What is Denetta?

Denetta is an IT infrastructure health and security audit platform developed by Bilgi Teknoloji. It audits infrastructure layers such as firewalls, network devices and domains with read-only access, produces concrete findings with expert rules, and combines them into a single 0-100 Infrastructure Health Score.

Does Denetta make changes to my devices?

No. It only reads: show/get/display commands, SNMP GET/WALK and read-only API calls. It never writes to a device and never attempts an active exploit. The remediation commands it suggests are only displayed.

Do I need to open ports on the customer network?

No. The collector installed on the customer network only talks outbound, over HTTPS on port 443. For FortiGate you can also start with a single backup file, with nothing to install.

All questions →

Let’s review your infrastructure together.

Let us show Denetta in a meeting with your own scenario and prepare a quote for your number of sites.